Назад
1 месяц назад

Principal Security Software Engineer (IAM)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Software Engineer (IAM): Defining and building production identity and access systems for Roblox's hybrid on-premises and cloud infrastructure with an accent on workload identity, privileged access, authorization, and AI-agent identity. Focus on designing mTLS and SPIFFE/SPIRE platforms, short-lived least-privilege access, resilient authorization, and secure identity lifecycle management for AI agents.

Location: United States; headquarters in San Mateo, California. Office-based roles are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday.

Company

Roblox builds a 3D immersive platform and tools that enable a global community of developers and creators to create interactive experiences.

What you will do

  • Define the architecture and multi-year strategy for machine, workload, human, and AI-agent identity across hybrid on-premises and cloud infrastructure.
  • Lead the SPIFFE/SPIRE-based workload identity platform, service-mesh integration, managed service accounts, and certificate issuance, storage, and rotation.
  • Architect just-in-time, least-privilege, and break-glass production access with short-lived, auditable credentials.
  • Evolve centralized authorization using RBAC, ABAC, and risk-based access models.
  • Design identity, scoped permissions, and session management patterns for AI agents.
  • Write RFCs and roadmaps, align platform stakeholders, mentor senior and staff engineers, and contribute hands-on to complex systems.

Requirements

  • 8+ years of professional experience building scalable, distributed backend systems and driving architecture end to end.
  • Deep expertise in identity and access management, including authentication, authorization, and access-control models.
  • Experience with PKI, certificate and key lifecycle management, mTLS, SPIFFE/SPIRE or comparable workload identity systems, service mesh, secret management, or privileged access management.
  • Proficiency in Go, Rust, Java, C++, Python, or C# .NET, with hands-on experience building systems.
  • Experience setting technical direction, writing design documents, leading technical work, and mentoring senior engineers.
  • AI fluency, including understanding LLM capabilities and limitations and the security implications of assigning identity and permissions to AI agents.

Nice to have

  • Bachelor's degree or equivalent experience in Computer Science, Computer Engineering, or a related technical field.

Culture & Benefits

  • Full-time employees are eligible for equity compensation and benefits.
  • Work emphasizes secure, reliable systems, least privilege, zero trust, and strong builder experience.
  • Role includes technical mentorship, cross-organizational collaboration, design reviews, on-call ownership, and hiring.
  • US work authorization restrictions may apply, and future H-1B sponsorship may not be supported.
  • Equal employment opportunities and reasonable accommodations are provided during the recruiting process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →